PT-2022-14473 · Google · Android

Published

2022-08-11

·

Updated

2023-08-08

·

CVE-2022-20250

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to improper input validation in the Messaging component, allowing files to be attached to messages without proper access checks. This could lead to local escalation of privilege with no additional execution privileges needed, requiring user interaction for exploitation.
Recommendations For Android version Android-13, consider restricting access to the Messaging component until a proper fix is applied, and ensure that all users are aware of the potential risk of attaching files to messages. As a temporary workaround, consider disabling the attachment feature in Messaging to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-20250

Affected Products

Android